Courseiva

Reduce Microsoft Sentinel Ingestion Cost: Basic Logs, Efficient KQL, and Daily Cap

Your Microsoft Sentinel workspace is experiencing high ingestion costs. Which of the following actions will most effectively reduce costs while maintaining security visibility?

⚠ Common exam trap

A common mix-up: candidates confuse reducing data retention (Option D) with reducing ingestion costs, but retention only affects storage charges, not the per-GB ingestion fee, which is the primary cost driver in Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Basic Logs for verbose logs like Windows events from non-critical servers.

Configuring Basic Logs for verbose logs (e.g., Windows Event ID 4688 from non-critical servers) reduces ingestion costs by storing them in a lower-cost tier while still retaining them for security investigations. Basic Logs are charged at a lower ingestion rate and support simple queries and search jobs, preserving visibility for incident response without the full cost of Analytics Logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete unused analytics rules to reduce log ingestion.

    Why it's wrong here

    Deleting unused analytics rules does nothing to reduce log ingestion because the data is already flowing into the workspace before any rule runs. Analytics rules are scheduled queries that consume CPU and may produce alerts, but they do not control which data sources are collected or how many events are stored. In fact, removing rules can reduce detection coverage, so the correct cost lever is to adjust the data collection configuration, not the rule set.

  • ✓

    Configure Basic Logs for verbose logs like Windows events from non-critical servers.

    Why this is correct

    Configuring Basic Logs for verbose Windows events from non-critical servers is the correct approach because Basic Logs use a lower-cost ingestion tier designed for high-volume, less-frequently queried data. These logs are stored in a separate table that supports simple search operations but avoids the full analytical query cost, dramatically lowering the per-gigabyte charge. This keeps the events available for incident response or compliance while reducing Sentinel's ingest bill, provided you do not need real-time alerting or rich KQL on that table.

  • ✗

    Disable collection of all informational logs.

    Why it's wrong here

    Disabling all informational logs is a blunt, high-risk change because Informational-level events frequently contain evidence of user activity, service installation, or network reconnaissance that security tools rely on. Attackers often trigger informational events during the early stages of an intrusion, so removing them altogether can cause blind spots in detection rules and hunting queries. A more targeted approach is to use data collection rules or transformations to filter only noisy, non-security-relevant event IDs rather than removing the entire severity class.

  • ✗

    Reduce the data retention period to 30 days.

    Why it's wrong here

    Reducing the data retention period to 30 days only lowers the cost of stored historical data; it has no effect on ingestion charges because every event is still collected, processed, and written to the workspace at the same rate. Shorter retention risks violating compliance obligations and destroys forensic evidence needed for long-running investigations. It also prevents retrospective hunting after an alert is discovered late, so the better solution is to retain high-value logs longer while moving verbose logs to cheaper Basic Logs.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are designing a Microsoft Sentinel deployment. You need to minimize ingestion costs while ensuring that all security-relevant events are collected. Which strategy should you use?

hard
  • A.Use Analytic Logs for all data sources to ensure full query capabilities
  • ✓ B.Use Basic Logs for verbose data sources like Windows firewall logs, and Analytic Logs for high-value security logs
  • C.Set short retention periods for all logs and export to storage
  • D.Collect only logs from Microsoft 365 Defender and ignore other sources

Why B: Microsoft Sentinel offers two log plan tiers: Analytic Logs (full KQL, alerts, workbooks) and Basic Logs (cheaper ingestion, limited query, 30-day retention). Placing high-volume, low-value sources like Windows firewall logs in Basic Logs and reserving Analytic Logs for high-value security events minimizes cost while still collecting all relevant data. This is the documented cost-optimization pattern.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.